Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

697 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.56%—LibarchiveRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux19/3/20261/9/2026
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory…
ModificadaAlta (7.5)1.1%—LibarchiveRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR Arm64+319/3/202628/9/2026
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the…
ModificadaAlta (7.1)0.19%—GNU BinutilsRedhat Openshift Container PlatformRedhat Enterprise Linux16/3/20261/9/2026
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure…
ModificadaAlta (7.1)0.19%—GNU BinutilsRedhat Openshift Container PlatformRedhat Enterprise Linux16/3/20261/9/2026
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially…
AnalizadaMedia (4.4)0.08%—IBM Planning Analytics Advanced Certified Containers10/3/202617/6/2026
IBM Planning Analytics Advanced Certified Containers 3.1.0 through 3.1.4 could allow a local privileged user to obtain sensitive information from environment variables.
AnalizadaMedia (6.7)0.40%—Microsoft ACI Confidential Containers5/3/202617/6/2026
'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (6.5)1.0%—Microsoft ACI Confidential Containers5/3/202617/6/2026
Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
AnalizadaMedia (6.7)0.60%—Microsoft ACI Confidential Containers5/3/202617/6/2026
Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
ModificadaMedia (6.5)0.47%—Redhat Openshift Container PlatformRedhat Enterprise LinuxLinux-nfs Nfs-utils4/3/20261/9/2026
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory,…
ModificadaMedia (5.9)0.19%—IBM APP Connect Enterprise Certified Containers OperandsIBM APP Connect Operator3/3/202617/6/2026
IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.20, and IBM App Connect Enterprise Certified Containers Operands versions CD 12.0.11.2‑r1 through 12.0.12.5‑r1 and 13.0.1.0‑r1 through 13.0.6.1‑r1, and LTS versions 12.0.12‑r1 through 12.0.12‑r20,…
AplazadaMedia (6.9)0.40%—SpinwasmAIContainerd-shim-spinAISpinroot SpinAI26/2/202617/6/2026
Spin is an open source developer tool for building and running serverless applications powered by WebAssembly. When Spin is configured to allow connections to a database or web server which could return responses of unbounded size (e.g. tables with many rows or large content bodies), Spin may in some cases attempt to…
ModificadaAlta (8.8)0.22%—Katacontainers Kata Containers19/2/202615/7/2026
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.27.0, an issue in Kata with Cloud Hypervisor allows a user of the container to modify the file system used by the Guest micro VM ultimately…
AnalizadaMedia (6.5)1.0%—Microsoft Confidential Sidecar Containers10/2/202617/6/2026
Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
AnalizadaMedia (6.9)0.36%—F5 Big-ip Container Ingress Services4/2/202617/6/2026
A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaBaja (2.3)0.18%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+174/2/202617/6/2026
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.8)0.50%—Katacontainers Kata Containers29/1/202617/6/2026
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.26.0, when a container image is malformed or contains no layers, containerd falls back to bind-mounting an empty snapshotter directory for the…
AplazadaAlta (8.5)0.38%—Kubevirt Containerized Data ImporterAI26/1/202615/7/2026
A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolumeClaims (PVCs) from unauthorized namespaces, resulting in unauthorized access to data via the DataImportCron PVC source mechanism.
AnalizadaAlta (7.8)0.28%—Apple ContainerApple Containerization23/1/202617/6/2026
The ArchiveReader.extractContents() function used by cctl image load and container image load performs no pathname validation before extracting an archive member. This means that a carelessly or maliciously constructed archive can extract a file into any user-writable location on the system using relative pathnames.…
AnalizadaAlta (8.7)0.79%—Linuxcontainers Incus22/1/202617/6/2026
Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host…
AnalizadaAlta (8.7)0.49%—Linuxcontainers Incus22/1/202617/6/2026
Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YAML configuration (e.g a member of the ‘incus’ group) can create an environment variable containing newlines, which can be used to add additional configuration items in…
AnalizadaBaja (2.9)0.46%—Redhat Hardened ImagesRedhat Jboss Core ServicesRedhat Openshift Container PlatformRedhat Enterprise Linux+315/1/20261/9/2026
A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly…
AnalizadaMedia (5.9)0.97%—Redhat Hardened ImagesRedhat Jboss Core ServicesRedhat Openshift Container PlatformRedhat Enterprise Linux+315/1/20261/9/2026
A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML…
AnalizadaBaja (3.7)0.54%—Xmlsoft Libxml2Redhat Hardened ImagesRedhat Jboss Core ServicesRedhat Openshift Container Platform+315/1/20261/9/2026
A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to…
AnalizadaCrítica (10)0.97%—Microsoft Azure Container Apps18/12/202517/6/2026
Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.
AplazadaAlta (7.5)0.28%—Foundry Container ServiceAI18/12/202517/6/2026
Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace to communicate with each other. This issue resulted in bypass of access control due to the presence of a vulnerable endpoint in Foundry Container Service that executed user-controlled commands…
Orbitaley — Vulnerabilidades